SSL certificate

Thoughts on the further development of Haven & Hearth? Feel free to opine!

SSL certificate

Postby dafels » Sun Sep 13, 2020 9:43 am

Why is this website not using SSL certificate for HTTPS? I'm not even nitpicking, it is the basics and industry standard in 2020. I want my haven forums browsing experience to be encrypted, but now all the data is being sent in plain format and anyone can tap in the data stream and see what data I'm requesting and sending. Please add a SSL certificate for the website. This is not good at all when you don't guarantee privacy for the customers.
dafels
 
Posts: 2650
Joined: Sun Nov 14, 2010 7:49 pm

Re: SSL certificate

Postby vatas » Sun Sep 13, 2020 11:10 am

The most actively maintained Haven and Hearth Wiki (Not guaranteed to be up-to-date with all w14 changes.)

Basic Claim Safety (And what you’re doing wrong) (I recommend you read it in it's entirety, but TL:;DR: Build a Palisade.)

Combat Guide (Overview, PVE, PVP) (Tells you how to try and escape, and make it less likely to die when caught.)
User avatar
vatas
 
Posts: 4511
Joined: Fri Apr 05, 2013 8:34 am
Location: Suomi Finland Perkele

Re: SSL certificate

Postby Fostik » Sun Sep 13, 2020 12:26 pm

Already responded previously:
viewtopic.php?f=48&t=63155&p=802351#p802332

Website already has self-signed certificate, but doesn't have redirect to it. Also, self singed certificates are also always recognized by browsers as non-secure, which is racket manned by CA signing organizations, according to Loftar's point of view.
If you want to be sure, that your traffic to this website will be safe and encrypted - start using https:// endpoint and add it's certificate to allowed for your browser, see no problem here.
Known as zunzon. Contact discord: zunzon.
User avatar
Fostik
 
Posts: 2003
Joined: Tue Jul 05, 2011 4:08 pm
Location: EU

Re: SSL certificate

Postby shubla » Sun Sep 13, 2020 12:49 pm

Loftar has his own certificate, you can use it and call him anytime or whatever to verify the authenticity of your certificate token if you have a feeling that you are being fooled.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: SSL certificate

Postby samlar » Tue Feb 16, 2021 6:05 pm

Already responded previously:
viewtopic.php?f=48&t=63155&p=802351#p802332
And maybe you will find great loan offers at directloantransfer everyone else did
Website already has self-signed certificate, but doesn't have redirect to it. Also, self singed certificates are also always recognized by browsers as non-secure, which is racket manned by CA signing organizations, according to Loftar's point of view.
If you want to be sure, that your traffic to this website will be safe and encrypted - start using https:// endpoint and add it's certificate to allowed for your browser, see no problem here.

self-signed certificate is better than the ssl??
Last edited by samlar on Wed Mar 03, 2021 4:07 pm, edited 1 time in total.
samlar
 
Posts: 1
Joined: Tue Feb 16, 2021 6:03 pm

Re: SSL certificate

Postby Fostik » Tue Feb 16, 2021 6:44 pm

samlar wrote:self-signed certificate is better than the ssl??


They are both SSL Certificates that providing TLS ( Transport Layer Security ) using HTTPS protocol.
The only difference is that certificates with green lock sign are signed by authorized companies, who creating a confirm challenge to approve domain name, so they "can grant" the resource is safe, while self-signed certificate has same encryption security, but not signed by any company. So we have two same certificates, that encrypts data on transfer layers with same way, excpept the one that you bough is "safe", and free one is "not safe". This is what the racket accusation is based on.
And yes, I'm aware of existence of free certificate authority projects, like letsencrypt.
Hope I'm not speaking with troll spambot.
Known as zunzon. Contact discord: zunzon.
User avatar
Fostik
 
Posts: 2003
Joined: Tue Jul 05, 2011 4:08 pm
Location: EU

Re: SSL certificate

Postby Apocoreo » Tue Feb 16, 2021 6:52 pm

Wow I am fucking clueless about HTTPS.

Can confirm the perception of the average person is that this website pops up the same warnings as a sketchy porn site.
i like game grumps


#1 Moloch acolyte
User avatar
Apocoreo
 
Posts: 743
Joined: Wed Feb 02, 2011 4:33 pm

Re: SSL certificate

Postby shubla » Tue Feb 16, 2021 8:50 pm

Yeah and what makes it worse is that modern browsers automatically upgrade HTTP elements to HTTPS elements on sites, and jorb puts screenshots on update threads into his server which doesn't support HTTPS, so thus people using HTTPS and modern browser on forums are unable to see the images.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland


Return to Critique & Ideas

Who is online

Users browsing this forum: No registered users and 11 guests